ZAP Scan warnings JAVA 25 issue

35 views
Skip to first unread message

Nathan

unread,
Jul 24, 2026, 9:10:44 AM (11 days ago) Jul 24
to ZAP User Group
Hi I posted about an issue I was having back in May, when I run ZAP scans via a command line I get the following warnings.

Found Java version 25.0.4-ea
Available memory: 7344 MB
Using JVM args: -Xmx1836m
WARNING: A terminally deprecated method in sun.misc.Unsafe has been called
WARNING: sun.misc.Unsafe::objectFieldOffset has been called by io.netty.util.internal.PlatformDependent0$4 (file:/usr/share/zaproxy/./plugin/network-beta-0.25.0.zap)
WARNING: Please consider reporting this to the maintainers of class io.netty.util.internal.PlatformDependent0$4
WARNING: sun.misc.Unsafe::objectFieldOffset will be removed in a future release

My scans also seem to take a lot longer to complete. (2 hours)

I was told this back in May,   "That's a Java 25 issue. We haven't addressed all the issues against 25 yet. 17 and 21 should both be fine."

is there any type of fix for this yet?

Currently I am running ZAP Version: 2.17.0

Here is the command I have been using for a while now,
owasp-zap -cmd -quickurl myurl -quickout /home/kalipurple/owasp/$(date +\%d.%m.%y)-myurl.html

Can anyone help please? 

Simon Bennetts

unread,
Jul 31, 2026, 10:13:43 AM (4 days ago) Jul 31
to ZAP User Group
Those are warnings from the netty add-on that we use for networking.
They have not fixed those warnings to date.
When they fix them then we'll update to a suitable version and the warnings should go away.

Re scan times taking longer - thats likely to be something else.
I am not aware of any changes that have significantly increased scan times.

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages